CVE Vulnerabilities

CVE-2023-35931

Cleartext Storage of Sensitive Information in an Environment Variable

Published: Jun 23, 2023 | Modified: Jul 04, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.

Weakness

The product uses an environment variable to store unencrypted sensitive information.

Affected Software

Name Vendor Start Version End Version
Shescape Shescape_project * 1.7.1 (excluding)

Potential Mitigations

References